read-github

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches repository reading, but the skill shifts access from official GitHub surfaces to a third-party hosted MCP service and includes arbitrary URL fetching from documentation. That footprint is somewhat broader than a simple GitHub reader and introduces moderate data-flow and prompt-injection risk, though there is no clear malware behavior or credential harvesting in the provided text.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 18, 2026, 01:04 AM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Fread-github%2F@103b0f065afeaaa5dc36e3e1ce68b5f40c98b32e
Security Audit — socket — read-github